Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

Debian: DSA-3265-1 Critical: Zend Framework Multiple Security Issues

debian
Calendar Grey May 20, 2015
Debian Logo
Debian Security Advisory DSA-3266-1 highlights several security flaws in the flask framework, urging users to apply the necessary patches.
Multiple vulnerabilities were discovered in Zend Framework, a PHP framework

Summary

CVE-2014-2681

Lukas Reschke reported a lack of protection against XML External
Entity injection attacks in some functions. This fix extends the
incomplete one from CVE-2012-5657.

CVE-2014-2682

Lukas Reschke reported a failure to consider that the
libxml_disable_entity_loader setting is shared among threads in the
PHP-FPM case. This fix extends the incomplete one from
CVE-2012-5657.

CVE-2014-2683

Lukas Reschke reported a lack of protection against XML Entity
Expansion attacks in some functions. This fix extends the incomplete
one from CVE-2012-6532.

CVE-2014-2684

Christian Mainka and Vladislav Mladenov from the Ruhr-University
Bochum reported an error in the consumer's verify method that lead
to acceptance of wrongly sourced tokens.

CVE-2014-2685

Christian Mainka and Vladislav Mladenov from the Ruhr-University
Bochum reported a specification violation in which signing of a
single parameter is incorrectly considered sufficient.

CVE-2014-4914

...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: zendframework
CVE ID: CVE-2014-2681 CVE-2014-2682 CVE-2014-2683 CVE-2014-2684

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here